Here’s some of the ways Talos is showing up at Black Hat, alongside our friends at Cisco and Splunk. This article has been indexed from Cisco Talos Blog Read the original article: Preview: Cisco Talos at Black Hat USA 2026
Category: Cisco Talos Blog
Chaos ransomware’s msaRAT: Living off the browser to build a covert C2 channel
The Chaos ransomware group uses new malware “msaRAT” that hijacks browsers. The malware doesn’t communicate directly with C2 but connects through the browser. It enables arbitrary command execution while hiding the attacker’s IP from victims via WebRTC over TURN. This…
Begun, the Patch Wars have
Long foretold, the Great Patching has begun and it’s a doozy. Buckle in as Joe takes you through the story. This article has been indexed from Cisco Talos Blog Read the original article: Begun, the Patch Wars have
UAT-11795 deploys novel Starland RAT and bespoke WLDR C2 implant in financially motivated campaign
Cisco Talos is disclosing UAT-11795, a sophisticated, Russian-speaking, financially motivated adversary that has been conducting a malicious campaign targeting users in the U.S. and Europe since at least June 2025. This article has been indexed from Cisco Talos Blog Read the original…
The Hunter’s Paradox: Is it time to embrace automated threat hunting?
Humans can no longer keep up with the volume and velocity of security data on their own, but AI can’t be fully trusted. David discusses the merits of both and muses on what the future might look like. This article…
Microsoft Patch Tuesday for July 2026 — Snort rules and prominent vulnerabilities
Microsoft has released its monthly security update for July 2026, which includes 622 vulnerabilities affecting a range of products, including 57 that Microsoft marked as "critical". Microsoft notes that two of the vulnerabilities disclosed this month have been exploited in…
[Video] Where protection starts: Cisco Talos Intelligence Integrations
Every day, defenders make high-consequence decisions with incomplete information. Learn how Cisco Talos Intelligence Integrations help reduce uncertainty by turning the latest threat intelligence into proactive protections across Cisco technologies. This article has been indexed from Cisco Talos Blog Read…
The serpent’s tongue: Luring the Python out of its den
This blog examines the full lifecycle of a Python package, from hosting on repositories such as PyPI or custom web servers, through source and wheel distribution formats, to the final installation into virtual or system-wide Python environments. This article has…
WolfSSL, GeoVision, VTK vulnerabilities
Cisco Talos’ Vulnerability Discovery & Research team recently disclosed three vulnerabilities in WolfSSF, fourteen in GeoVision, and one vulnerability in VTK-DICOM. The vulnerabilities mentioned in this blog post have been patched by their respective vendors, in adherence to Cisco’s third-party…
Winning 54% of the time
With Wimbledon’s help, Hazel argues against the popular myth that “Attackers only need to be right once, but defenders need to be right 100% of the time.” This article has been indexed from Cisco Talos Blog Read the original article:…
UAT-7810 continues building ORB networks using new malware
Talos’ latest findings on UAT-7810 indicate that the threat actor continues to develop their custom-made malware. This article has been indexed from Cisco Talos Blog Read the original article: UAT-7810 continues building ORB networks using new malware
Catan and Mouse
What do board games and cybersecurity have in common? Pattern recognition. Strategy. Adaptation. In this week’s Threat Source Bill explores why curiosity may be a defender’s most valuable skill. This article has been indexed from Cisco Talos Blog Read the…
ARToken: Inside an EvilTokens affiliate panel targeting Microsoft 365
Cisco Talos identified a fully-featured phishing-as-a-service (PhaaS) operator panel, branded "ARToken," that shares infrastructure, API contracts, and operational patterns with the EvilTokens platform documented by Sekoia and Microsoft in early 2026. The ARToken panel exposes 80+ API endpoints for device…
Martin Lee: Running through the Arctic (and the threat landscape)
Ever wonder how someone goes from studying human viruses to leading cybersecurity teams? In this Humans of Talos, we’re joined by Martin Lee, EMEA Lead, to talk about his journey into the industry. This article has been indexed from Cisco…
Beyond IOCs: AI-enabled threat intelligence
In this week’s newsletter, Martin considers how AI will help threat intelligence by creating an easily queryable data source of intelligence reports. This article has been indexed from Cisco Talos Blog Read the original article: Beyond IOCs: AI-enabled threat intelligence
Introduction to COM usage by Windows threats
Component Object Model (COM) is a fundamental Windows technology used by legitimate applications for object activation, inter-process communication, automation and language-independent component reuse. Those same qualities make it useful to threat actors. This article has been indexed from Cisco Talos…
Close Encounters of the Human Kind
In the latest Threat Source, Hazel channels her inner Spielberg to explore why humans are delightfully irrational, reminding us that while security best practices are simple in theory, they’re a lot harder to pull off when you’re busy dealing with…
Scripting the disassembler: Local agentic reverse engineering through vbdec’s live COM object model
Cisco Talos detailed a new approach to reverse engineering that pairs local AI agents with traditional analysis tools like the VB6 disassembler vbdec. Instead of awkwardly bolting AI onto the software, vbdec exposes its parsed data through a live COM…
A tale of two eras
In this week’s newsletter, Amy reminisces on the tech toys of their childhood, inspired by a hilarious lesson about why your digital privacy shouldn’t be left on an open channel. This article has been indexed from Cisco Talos Blog Read…
Microsoft Patch Tuesday for June 2026 — Snort rules and prominent vulnerabilities
Microsoft Patch Tuesday details for June 2026. This article has been indexed from Cisco Talos Blog Read the original article: Microsoft Patch Tuesday for June 2026 — Snort rules and prominent vulnerabilities
